WordPress Plugin Vulnerabilities

Chained Quiz < 1.1.9.1 - Authenticated Stored XSS

Description

WordPress Plugin Plugin Chained Quiz latest (1.1.9) and before suffers from a Stored XSS vulnerability in the sender_name, admin_subject and user_subject POST parameter when an admin completes the setting for plugin (as a result, the severity is very low)

Proof of Concept

Affects Plugins

Fixed in 1.1.9.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
khoabda
Submitter
khoabda
Submitter website
Verified
No

Timeline

Publicly Published
2020-02-21 (about 6 years ago)
Added
2020-02-22 (about 6 years ago)
Last Updated
2020-02-22 (about 6 years ago)

Other